skip to content

Explain the mirrorOf matching syntax, including external:* and negation. How do you mirror everything except one internal repo?

level: middleimportance: should knowfreq 55%

answer

  1. matched against repo id
  2. *, external:*, external:http:*
  3. comma list of ids
  4. negation !id with *
  5. first match wins

basics

~10 s

mirrorOf decides which repository ids a mirror handles. Use * for all, external:* for non-local ones, a comma list of ids, or *,!internal to mirror everything except the repo with id 'internal'.

solid answer

~40 s

`<mirrorOf>` is a pattern matched against each declared repository's `<id>`. Supported forms: a single id (`central`); `*` (all repos); `external:*` (all except `localhost` and `file://` repos); `external:http:*` (external plain-HTTP only); a comma-separated id list (`repo1,repo2`); and negation with `!` (`*,!internal`). To mirror everything except an internal repo you write `<mirrorOf>*,!internal</mirrorOf>`, which keeps the `internal` repository resolving directly to its own URL while routing all others through the mirror. `external:*` is the practical default for corporate setups because it leaves local file repositories and integration-test localhost repos untouched. Only the first matching mirror is applied, so when multiple mirrors exist, ordering and specificity matter.

code

xml · 5 lines
xml
<mirror>
  <id>corp-nexus</id>
  <url>https://nexus.corp.example/repository/maven-public/</url>
  <mirrorOf>*,!internal-snapshots</mirrorOf>
</mirror>

go deeper

for a junior

Knows * means all repositories.

for a middle

Can write external:* and *,!id patterns and explain what each excludes.

for a senior

Orders mirrors for first-match correctness and avoids breaking localhost/file test repos.

for a principal

Standardizes a mirrorOf convention across the org and audits for overlapping/shadowing mirrors.

## The mirrorOf grammar Maven evaluates `<mirrorOf>` against the **id** of each repository it is about to contact. The accepted tokens: - **`<id>`** — exact id match, e.g. `central` mirrors only the Central repository. - **`*`** — wildcard, matches every repository. - **`external:*`** — matches every repository **whose URL is not** `file://` and **whose host is not** `localhost`/`127.0.0.1`. Useful so that locally served test repos still resolve directly. - **`external:http:*`** — same as above but restricted to plain-`http` URLs (not `https`); rarely needed. - **comma list** — `repo1,repo2,central` matches any of those ids. - **negation `!id`** — excludes an id. Combine with `*`: `*,!internal` = everything except `internal`. ## Combining patterns Patterns are comma-separated and evaluated left to right; a later negation can subtract from an earlier wildcard. Common recipes: - `*` — funnel literally everything through the manager (also mirrors plugin repos and local test repos). - `external:*` — funnel external repos only; safest general corporate setting. - `*,!snapshots` — mirror everything but let a repo id `snapshots` resolve directly. ## First-match wins If several `<mirror>` entries could match, Maven uses the **first** one in document order that matches. So put more specific mirrors before broad ones. Two mirrors with overlapping `mirrorOf` is a frequent misconfiguration. ## Example: mirror all but one internal repo ```xml <mirrors> <mirror> <id>corp-nexus</id> <url>https://nexus.corp.example/repository/maven-public/</url> <mirrorOf>*,!internal-snapshots</mirrorOf> </mirror> </mirrors> ``` Here a repository declared in the pom with `<id>internal-snapshots</id>` keeps using its own URL, while Central, plugin repos, and any third-party repos go through Nexus. ## Why external:* matters Integration tests sometimes spin up a `file://` or `http://localhost` repository. With `*` those would be (wrongly) redirected to the corporate manager and break. `external:*` leaves them alone.

  • What does external:* exclude that * does not?
    Repositories on localhost/127.0.0.1 and those using file:// URLs are left to resolve directly.
  • If two mirrors both match a repo, which one is used?
    The first matching mirror in settings.xml document order; remaining matches are ignored.

saying these in an interview costs you the question

  • Claiming mirrorOf matches repository URLs (it matches ids)
  • Thinking negation works alone without a wildcard
  • Believing all matching mirrors are merged rather than first-match-wins

context